瑞星卡卡安全论坛
我有问题请教你 - 2008-11-25 20:44:00
:kaka10: :kaka10: :kaka10: 气死我了,这是什么呀
heiheimomo - 2008-11-25 20:48:00
电信真TM下流。。。。。。。。
超级游戏迷 - 2008-11-25 20:48:00
请楼上诸位看看41楼、55楼、56楼,先与当地ISP(网络运营商)联系并咨询相关情况……:default7:
habtw - 2008-11-25 20:48:00
碰鬼了,我徐汇的,昨天晚上开始就出现这个问题了,我用上海电信ADSL的宽带,2M的
tanyaT - 2008-11-25 20:54:00
:kaka2: 就是说一定不会是毒了是吗?
gfdcj - 2008-11-25 20:56:00
我换了火狐就没问题了
benzwk - 2008-11-25 21:08:00
徐汇ADSL
我用IE7.0就有这个问题
用谷歌浏览器好像没这个问题
另外,我的BT下载速度也非常慢了,不知道大家是不是这样
tanyaT - 2008-11-25 21:10:00
:kaka3: 有谁可以告诉我,为什么只有IE会有这样的问题?
到底是不是病毒啦?
超级游戏迷 - 2008-11-25 21:14:00
建议按我在63楼所说的,先问问ISP……:default21:
terado - 2008-11-25 22:01:00
About it working in Firefox... It seems to be no problem, but the same code is being sent to firefox - it just seems to not break. Im actually glad that IE breaks else we would never know there is something suspicious.
It seems possible that ipc.jsp is Java's Inter-Portlet Communication:
http://docs.jboss.org/jbportal/v2.2/reference-guide/en/html/ipc.htmlIm not sure exactly what this is doing. I think if this was successful and loaded the page we can see what the code is... Once this stops happening I intend to keep watching what's happening here, hope others are interested too :)
尧雨 - 2008-11-25 22:17:00
不管是电信还是病毒,都要给个解决方法吧。。。:default11:
ursaminor - 2008-11-25 22:26:00
特地注册了一个,
我的问题和大家一样
抓包看了一下,在出问题的时候可以看到以下连续两个包:
#4115(18.194769):192.168.0.2->202.120.58.161 HTTPGET /bbstdoc?board=IS HTTP/1.1
Accept: ...
Referer: [url]http://bbs.sjtu.edu.cn/bbsdoc?board=IS[/url]
Accept-Language: zh-cn
UA-CPU: x86
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
Host: bbs.sjtu.edu.cn
Connection: Keep-Alive
Cookie: (ommited)
#4116(18.200341):202.120.58.161->192.168.0.2 HTTPHTTP/1.1 200 OK
Cache-Control: no-cache
Content-Type: text/html
Content-Length: 352
<html>
<script>function i(){document.title=window.frames[1].document.title;}</script>
<frameset framespacing='0' border='0' rows='0,100%' frameborder='0'>
<frame name='pFrm' src='http:///nhds/ipc.jsp?ref=1 scrolling='no'>
<frame name='oFrm' src='http://bbs.sjtu.edu.cn/bbstdoc?board=IS& onload='i();
' scrolling='auto'>
</frameset>
</html>
和terado 说的一样,这段代码显然就是在当前窗口里除了显示要访问的页面以外另外开一个frame(可能是不可见的),然后转到'
http:///nhds/ipc.jsp?ref=1去,如果不是我的计算机被劫持了,就是电信干的
另外我倒觉得他把那个'
http:///nhds/ipc.jsp?ref=1 做好可以用来统计所有人都上过什么网站,但是我觉得ISP没必要这样统计因为他本来就能获得一手资料,所以比较疑惑
gfdcj - 2008-11-25 22:38:00
用火狐也有问题,看小说按下一页会跳到其他页面,和IE问题不一样,看来不是病毒就是网络问题
terado - 2008-11-25 22:42:00
To post #72
You are right that they already have statistics, but consider this "nhds" page loaded correctly it could be fetching information from the other frame. This would be far more than simple statistics and potentially a big security risk. If they are modifying the code of webpages before they come back so that they can spy on the other frame, this is very bad news.
diablo2000 - 2008-11-25 22:47:00
我也中招了,以为是病毒,忙乎了半天。。。
diablo2000 - 2008-11-25 22:50:00
原来也出现了乱码现象。
IE7.0下面菜单查看--编码--自动选择,打勾。然后选择简体中文。修改后就没出现过了。
各位可以试试看。
jojochou - 2008-11-25 22:51:00
长宁,VISTA, IE7
jojochou - 2008-11-25 22:56:00
果然~~改了编码就好了~~~
贝贝爱莹莹 - 2008-11-25 22:59:00
长宁区 电信ADSL VISTA 24号晚上发现的问题,特此注册
zg1_2004 - 2008-11-25 23:02:00
该用户帖子内容已被屏蔽
无量电信垄断 - 2008-11-25 23:02:00
NND,我也中标了,NOD32和360都没查出来什么后,还特意去下了什么“木马克星”“木马专家”等山寨软件折腾了一晚,最后又跑这陌生地方来注册发言:default3:
我累啊...
长宁ADSL、D版XP、IE7
ursaminor - 2008-11-25 23:08:00
原帖由 terado 于 2008-11-25 22:42:00 发表
To post #72
You are right that they already have statistics, but consider this "nhds" page loaded correctly it could be fetching information from the other frame. This would be far more tha......
对的。。。就和以前某木马能在GOOGLE返回搜索结果里做点小动作把自己广告加上去再在IE显示一样。。。的确很恶心,
还可以用来放恶意代码,或者窃取COOKIES什么的 = =
不知道用HTTPS的网页会不会也出这个问题```
感觉百分百 - 2008-11-26 0:40:00
告诉大家一个好消息,问题似乎已经解决了,我0点30分到现在好像没有这个问题了,看来电信已经搞好了,不知道其他朋友是否和我一样。
ursaminor - 2008-11-26 1:02:00
没好。。。
老白同志 - 2008-11-26 4:52:00
我也上海的 长宁区的电信adsl
中国电信就会干这种事情 r!
Stoneaijun - 2008-11-26 8:33:00
兄弟们啊,我也有了,不知道什么东西啊,你们知道吗?我也是24号那天开始有的,本来以为是病毒,换了3个杀毒软件都没有用。系统重装才3个月,再装一次。。。。不高兴啊
Stoneaijun - 2008-11-26 8:34:00
补充一点,我是普陀的ADSL
heiheimomo - 2008-11-26 8:37:00
普陀ADSL,今天情况仍然存在
heiheimomo - 2008-11-26 8:38:00
大家都去投诉10000吧,不投诉不行的,电信就是这样子,态度要凶一点。
vanished - 2008-11-26 9:03:00
To terado
do u actually think the phone company is trying to spy on what we r viewing? sorry i'm no technical
guy, but that bombs me hard if this truely is the case. or in a worse senario, could somebody hijack
the normal response and return information that they want us to see by hacking this frame? say a
registration page, or even bank notice? can u place more details about this nhds, i can help translate.
thank you!
现在是早上9点5分了,情况还是存在,而且现在出现nhds,点后退以后,网页会全变成繁体字,要再
刷新一下才能恢复正常。电信到底想干嘛啊?
© 2000 - 2026 Rising Corp. Ltd.